CVE-2026-0272: medium-severity vulnerability in Palo Alto Networks PAN-OS
PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI)
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6epss 0.3%
exploitation probability
0.3%top 84% of all CVEs
observed exploitation
nono source reports it
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges.
The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:C/RE:M/U:Amber
Affected products
Palo Alto Networks · Cloud NGFWPalo Alto Networks · PAN-OSPalo Alto Networks · Prisma AccessRelated CVEs — Palo Alto Networks PAN-OS
In the same product, most dangerous first.
CVE-2024-3400CRITICALPAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtectEPSS 100.0%KEVCVE-2024-0012CRITICALPAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)EPSS 99.9%KEVCVE-2025-0108HIGHPAN-OS: Authentication Bypass in the Management Web InterfaceEPSS 98.5%KEVCVE-2026-0257HIGHPAN-OS: GlobalProtect Authentication Bypass VulnerabilitiesEPSS 96.9%KEVCVE-2024-9474MEDIUMPAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management InterfaceEPSS 94.8%KEVCVE-2026-0300CRITICALPAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication PortalEPSS 31.7%KEV